
Sr Product Security Engineer
- Business Unit: Draeger Medical Systems, Inc., Job-ID: 1352
- Location: Andover
- Function: R&D
- Work Location: Hybrid
- Employment Type: Permanent
The Job Responsibilities
We are hiring a Senior Product Security Engineer to work hybrid, 3 days a week, in our Andover, MA office.
The Senior Product Security engineer helps secure patient monitoring medical device solutions and connected health software throughout the product lifecycle. This role partners directly with systems, software, and test engineering teams to build security into product architectures, generate objective evidence for regulatory submissions, and maintain product cyber resilience after release.
The selected candidate will support the integration of advanced cybersecurity controls, identify and mitigate vulnerabilities, and contribute to initiatives that improve cyber resilience across the product lifecycle. This person will serve as a technical subject matter expert, collaborate across functions, and help drive long-term improvements in product security posture.
This is a product security engineering role; it is not focused on enterprise IT security.
Main Responsibilities:
• Product Security - Implement security requirements across the medical device development lifecycle by partnering with cross-functional teams and applying best practices from design through deployment.
• Perform threat modeling, attack-surface analysis, and product cybersecurity risk assessments. Define security requirements and risk controls, and integrate cybersecurity risks with product safety risk management.
• Support the design and delivery of secure medical devices through implementation of capabilities such as secure boot, secure communications, data protection, software update mechanisms, system integration protections, and access controls.
• Plan and review cybersecurity testing, including vulnerability scanning, software composition analysis, fuzzing, and penetration testing. Drive remediation and confirm closure through retesting.
• Maintain product SBOMs and assess reported vulnerabilities. Determine product impact, prioritize remediation, and support coordinated vulnerability disclosure and postmarket monitoring.
• Prepare and review cybersecurity documentation for FDA and other regulatory submissions. Respond to regulator and customer cybersecurity questions.
• Serve as a technical subject matter expert. Work with engineering, test, quality, regulatory, service, legal, and program management teams to resolve product security risks.
• Improve product security processes, tools, and reusable engineering practices based on emerging threats, standards, and regulatory expectations.
Your Qualifications
Education
Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, Electrical Engineering, Software Engineering, or a related technical field, or equivalent practical experience.
Required Qualifications
• 3 to 6 years of experience in product security, application security, embedded security, or security engineering in a product development environment
• Experience with threat modeling, cybersecurity risk assessment, secure design, vulnerability analysis, and security testing.
• Working knowledge of embedded, Linux, Windows, real-time, or network-connected systems, including common network security principles and protocols.
• Understanding of secure development lifecycle and security-by-design practices.
• Ability to communicate technical risks clearly, develop traceable documentation, and support multiple assignments in a cross-functional environment.
Preferred Qualifications
• Experience developing or securing medical devices, safety-critical products, or products in another regulated industry.
• Experience supporting FDA and other global medical device cybersecurity submissions and responding to regulatory questions or deficiencies.
• Familiarity with IEC 81001-5-1, AAMI TIR57, applicable FDA cybersecurity requirements and guidance, NIST publications.
• Hands-on experience with secure product implementation, security testing, SBOM or software composition analysis tools, and vulnerability remediation.
• Programming or scripting experience and relevant cybersecurity certifications such as CSSLP, GPEN, or Security+.
The targeted pay range for this position is typically between $115,000 - $127,000. We note that the base pay offered is based on market location and may vary further depending on individualized factors for job candidates, such as job-related knowledge, skills, experience, and other objective business considerations. This position is eligible for the following additional compensation: annual pay.
Dräger Benefits
- Medical, dental, and vision insurance
- Life, short- and long-term disability coverage
- 401(k) with company match
- Over 4 weeks of paid time off, plus holidays and parental leave
- Flexible spending accounts and employee assistance program
Who we are
Interested?
Please, apply directly through our career portal.
We look forward to receiving your application.
Nearest Major Market: Boston